Burning Bridges - Stopping Lateral Movement via the RPC Firewall

Burning Bridges - Stopping Lateral Movement via the RPC Firewall

Black Hat via YouTube Direct link

RPC Can't Be Easily Blocked

8 of 25

8 of 25

RPC Can't Be Easily Blocked

Class Central Classrooms beta

YouTube videos curated by Class Central.

Classroom Contents

Burning Bridges - Stopping Lateral Movement via the RPC Firewall

Automatically move to the next video in the Classroom when playback concludes

  1. 1 Intro
  2. 2 whoareyou.exe?
  3. 3 Remote Procedure Call
  4. 4 DCE/RPC Terminology
  5. 5 Runtime Library
  6. 6 Resources and Tools
  7. 7 RPC attacks demo
  8. 8 RPC Can't Be Easily Blocked
  9. 9 Why a Talk on RPC?
  10. 10 No OOTB Events
  11. 11 RPC ETW Incomplete
  12. 12 RPC hunting is hard
  13. 13 If You Can't Detect, Can You Block ?
  14. 14 RPC Filters are buggy / lacking
  15. 15 Goals
  16. 16 RPCFirewall Quick Demo
  17. 17 RPCFW Internals
  18. 18 Event Logs
  19. 19 Debug Messages
  20. 20 Commands
  21. 21 Configuration
  22. 22 No Performance Penalty (audit:false)
  23. 23 Other Considerations
  24. 24 Research Cycle
  25. 25 Example: Creating Deny Lists

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.